FortiGate ๆฏไผๆฅญ็ถฒ่ทฏไธญๆๅธธ่ฆ็้ฒ็ซ็ไนไธ, ๆไพๅผทๅคง็ๅฎๅ จ็ญ็ฅ、ๆต้ๆง็ฎก่่จบๆทๅ่ฝ。 ๆฌ็ฏๆด็ CLI(Command Line Interface) ็ๅฎๆดๆไปค้, ๅพๅธณ่่ไป้ข็ฎก็ๅฐๅฐๅ ๅๆ,ๅๅฉๅทฅ็จๅธซๅฟซ้ๆๆก็ณป็ตฑ้ไฝ่้ค้ฏๆๅทง。
๐ค ไธ、ๅธณ่่็ณป็ตฑ็ฎก็
็จๆผๆชข่ฆ็ณป็ตฑ็ๆ 、็ๆฌ、ๅธณ่่ๆฌ้่จญๅฎ:
get system status get system performance status config system admin show end
ๅปบ็ซๆฐ็ฎก็ๅธณ่:
config system admin edit admin2 set password MyStrongPassword set accprofile super_admin set vdom root next end
set accprofile ๆๅฎๆฌ้ๅฑค็ด(ๅฆ read_only、super_admin)。
- ้ๅ two-factor ๅฏๆๅๅฎๅ
จๆง。
๐ ไบ、็ถฒ่ทฏไป้ข่ VLAN ่จญๅฎ
ๆฅ็็ถฒ่ทฏไป้ข่็ๆ :
show system interface get system interface physical diagnose hardware deviceinfo nic port1 get system arp
่จญๅฎ้ๆ IP ๆ VLAN:
config system interface edit port1 set ip 192.168.1.1/24 set allowaccess ping https ssh http set alias LAN next edit vlan10 set vdom root set interface port1 set vlanid 10 set ip 10.10.10.1/24 next end
✅ ๆชขๆฅ:
ไฝฟ็จ execute ping 8.8.8.8 ๆธฌ่ฉฆๅค้จ้ฃ็ทๆฏๅฆๅฏ้。
๐งฑ ไธ、้ฒ็ซ็ Policy ็ฎก็
ๅๅบ็พๆ็ Policy ่่ฉณ็ดฐๅ งๅฎน:
show firewall policy show firewall policy 10
ๅปบ็ซๆฐ้ฒ็ซ็ Policy:
config firewall policy edit 10 set name Allow-Web set srcintf "port1" set dstintf "port2" set srcaddr "all" set dstaddr "all" set service "HTTP" "HTTPS" set action accept set schedule "always" set nat enable next end
✅ ๅปบ่ญฐ:
- Policy ้ ๅบๅฝฑ้ฟๆต้ๅน้ ,็ขบไฟๅ ่จฑ่ฆๅๅจ้ปๆ่ฆๅไนๅ。
- ๅฏ็จ
diagnose sys session list | grep x.x.x.xๆฅ็ๆฏๅฆ่ขซๅน้ 。
๐ฐ️ ๅ、่ทฏ็ฑๆชขๆฅ่ๆต้่ฟฝ่นค
ๆฅ็้ๆ ่ๅๆ ่ทฏ็ฑ่กจ:
get router info routing-table all show router static get router info routing-table details 10.1.1.0
่ฟฝ่นคๅฐๅ ่ทฏๅพ:
execute traceroute 8.8.8.8 execute ping 192.168.1.10
✅ ๅฐๆๅทง: ่ฅๆพไธๅฐ่ทฏ็ฑ,ๅฏๆชขๆฅ Default Route ๆ Policy ๆฏๅฆๆพ่ก。
๐ก ไบ、ๅฐๅ ๅๆ่ Debug Flow
ๆๅธธ็จ็่จบๆท่ๅฐๅ ่ฟฝ่นคๆไปค:
diagnose sniffer packet any '(src host 10.1.1.10 or dst host 192.168.10.20)' 4 0 diag debug enable diag debug flow show console enable diag debug flow filter addr 192.168.1.100 diag debug flow trace start 100
ๅๆญข debug:
diag debug disable
✅ ๅปบ่ญฐ:
sniffer packet้ฉๅๅฟซ้่งๅฏๅฏฆ้ซไป้ขๆต้。debug flowๅฏ็ฒพๆบ่ฟฝ่นค Policy ่ NAT ๆตๅ。- ๅฏๆผ GUI → Packet Capture ๅฏๅบ
.pcapๆชๅๆ。
๐งฐ ๅ ญ、็ณป็ตฑ่จบๆท่ๆ่ฝ็ฃๆง
ๅณๆ็ฃๆง็ณป็ตฑๆ่ฝ่้ฃ็ท็ๆณ:
get system performance status diag sys top diag sys session stat
ๆธ ้ค้ๅค session:
diag sys session clear
✅ ๆ็คบ:
่ฅ CPU ๆ่จๆถ้ซไฝฟ็จ็็ฐๅธธ,ๅฏ็จ diag sys top ่งๅฏๅ้ก้ฒ็จ。
๐ ็ต่ช
็ๆ FortiGate CLI ๆไปค,่ฝ่ฎ็ถฒ็ฎก่่ณๅฎๅทฅ็จๅธซๆดๅฟซๅฎไฝๅ้ก、้ฉ่ญ่จญๅฎไธฆ้ฒ่กๆ่ฝ่ชฟๆด。 ็ก่ซๆฏๅธณ่็ฎก็、Policy ๅปบ็ฝฎๆๅฐๅ ๅๆ,CLI ็ๆไพๆฏ GUI ๆด็ดฐ็ทป็่จบๆท่ฝๅ。 ๅปบ่ญฐๆฅๅธธ็ถญ้ไธญ,ๅฎๆๅฐๅบ่จญๅฎๅไปฝ่็ฃๆงๆไปค่ผธๅบ,็ขบไฟ็ถฒ่ทฏ็ฉฉๅฎ่ๅฎๅ จ。
— WWFandy・็ถฒ่ทฏ่่ณๅฎ็ญ่จ
ๆฒๆ็่จ:
ๅผต่ฒผ็่จ